Case Study
Nonprofit Healthcare Provider
Meeting Regulatory Requirements with a Zero Trust Architecture
healthcare

The Mission 

For nonprofit healthcare, every investment matters. Technology has to support the teams responsible for patient care while meeting the demands of a heavily regulated environment. That balancing act became especially important for one nonprofit provider. It was facing regulatory requirements from the Office of the Inspector General for 28 of its applications. Zero Trust architecture seemed to be the right way forward. But the client realized early on that achieving a stronger security posture would take a controlled, thoughtful plan in order to get there. 

Vital Signs 

The work itself would take careful coordination across people, processes, and technology. 

Many Moving Parts. Improving cybersecurity for 28 applications would first mean fully understanding these applications. That involved the controls supporting each one, including access decisions, supporting infrastructure, control ownership, and the client’s ability to monitor and respond. 

A Missing Baseline. Beyond the applications, the client needed a structured assessment of its existing processes and technology investments. Establishing a shared baseline would make it easier to prioritize critical work. 

Existing Investments. That shared baseline was especially important because the client had made significant product investments. The future architecture would need to build on what was already in place and working. 

A Target State for the Real World. Zero Trust means never trust, always verify. On its surface, that makes sense. But how does it actually work day-to-day for a healthcare provider? The client wanted to understand which controls to improve first, which policies to formalize, and how to sequence changes without disrupting its critical work. 

It was a fine balance: respond to immediate audit requirements while building a security program that could keep maturing over the next several years, without creating competition for limited attention and budget. Healthcare doesn’t have downtime. Before any procedure, care providers need a clear plan that explains exactly what it entails, what success will look like, and how each team’s role contributes to the outcome. 

The Treatment Plan 

This engagement aligned with three areas of AHEAD’s expertise. 

  • Secure & Resilient Architectures: Applying NIST SP 800-207 and the CISA Zero Trust Maturity Model to define a practical security architecture and maturity roadmap. 
  • Operational Excellence: Connecting cybersecurity goals to governance, ownership, and repeatable workstreams. 
  • Platform & Workload Modernization: Using existing product investments where they fit, so new investment could be directed toward current gaps. 

The work unfolded across three phases: 

Advise 

AHEAD began by sitting down with the client for a series of discovery and assessment workshops. Like with a medical procedure, this process defined responsibilities, gathered data, reviewed documentation, and clarified the assessment scope and requirements for operating the environment. The workshops also gave the various teams room to surface new needs and additional capabilities. Zero Trust depends on how a control works in practice, who owns it, and what happens when the normal path stops being normal. 

Why the Groundwork Mattered: AHEAD translated those discussions into a current-state view of the client’s maturity. The recommendations were grounded in the actual environment, not a theoretical model. 

Build 

AHEAD then used the assessment findings to create a prescriptive roadmap. The CISA Zero Trust Maturity Model helped structure findings and recommendations. NIST SP 800-207 provided the conceptual backbone and common language for the assessment, while the CISA model helped turn that language into specific maturity guidance and roadmap activities. The plan identified specific workstreams and activities across a three-year horizon, with the sequencing needed to move from initial preparation toward broader enforcement and automation. 

How It Came to Life: The assessment showed where the client could build on existing investments, where those investments could support the new architecture, and which additional capabilities could close the remaining gaps. The roadmap connceted technical goals to organizational ones, along with the governance, roles, and operating practices needed to sustain them. 

Run 

The client was now ready to execute its Zero Trust roadmap in three initial phases: 

Phase One: Plan and Prepare. Establish governance and the conditions required for new or enhanced Zero Trust capabilities. 

Phase Two: Collect and Deploy. Extend functionality while gathering the data and logs needed to improve visibility and enforcement. 

Phase Three: Develop and enforce. Introduce automation and enforcement as the organization matures and builds operating capacity. 

How It Kept Delivering: AHEAD’s roadmap gave the organization a progressive sequence of work, with room to adjust and respond to changes, implementation blockers, budget constraints, and the demands of daily healthcare work. 

A Healthier Outlook 

The client emerged from the assessment with a three-year plan that was ready for action. 

A Framework That Can Scale. The client’s plan addresses specific workstreams and activities tied to its industry and regulatory requirements. It also supports future audit readiness and sustained progress, with a repeatable way to extend Zero Trust across additional applications and technology domains. 

A Shared Security Language. Using NIST SP 800-207 and the CISA Zero Trust Maturity Model gave leadership and technical teams a common way to discuss current state, desired state, controls, and next steps. 

Investment Priorities. The roadmap meant the organization could distinguish early-stage work from later-stage capabilities. This made it easier to sequence resources and decisions across the program. By leveraging existing products and investments, the client could focus new spending on meaningful gaps. 

What’s Next 

The client is progressing through the roadmap’s planned workstreams. As the program matures, it can expand control coverage, improve visibility, introduce additional automation, and move toward consistent enforcement of Zero Trust principles.  

A well-executed Zero Trust program can help nonprofit healthcare organizations make strategic cybersecurity decisions, improve accountability, and respond to changes in the threat landscape. AHEAD turns that balancing act into a roadmap that’s practical enough to execute, structured enough to measure, and flexible enough to keep evolving. 

Top Takeaways

AHEAD:

  • Created a three-year roadmap to address the Office of the Inspector General’s cybersecurity requirements for 28 applications. 
  • Assessed existing people, processes, and technology using NIST SP 800-207 and the CISA Zero Trust Maturity Model. 
  • Turned Zero Trust goals into specific workstreams, activities, dependencies, and maturity goals. 
  • Leveraged existing product investments so spending could address current gaps instead.